Resource Library
ReportsComplianceVisibilityFebruary 13, 2024

Bringing ORDR to CMMC Compliance for Unmanaged Devices

WHITEPAPER

Introduction

The Cybersecurity Maturity Model Certification (CMMC) defines a particularly broad set of security requirements that apply to virtually any organization that does business with the U.S. Department of Defense. Originally published in January of 2020, the CMMC Version 1.02 aims to bolster the security of the extended DoD supply chain, which has increasingly come under attack from a wide range of malicious actors. CMMC is expected to be implemented by more than 300,000 companies that make up the Defense Industrial Base (DIB) that provides support for the DoD.

The CMMC framework’s overarching goal is to protect federal information that resides in an organization’s environment, including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Any computer or electronic device that processes federal data considered sensitive will need to be protected from the associated range of many threats. Organizations will need to consider a wide range of security best practices when developing their compliance strategies, including traditional managed devices, unmanaged devices, network, IoT and OT devices.

Many organizations today lack visibility, understanding and control of their devices as to what data or information is flowing in and out of their organization.

This paper shows how the ORDR Systems Control Engine (SCE) fills the gaps for CMMC requirements.

CMMC Levels

The CMMC is built on a multidisciplinary maturity model approach to security that aims to establish an overall security framework for DIB organizations. It is particularly broad in scope, covering a variety of security capabilities and best practices across 17 security domains. Domains include practices for technical controls implemented through hardware or software, such as vulnerability scanning and behavioral threat detection. Domains also include practices for organizational controls to develop policies, plans and the human aspects of security, such as security training and situational awareness.

CMMC recognizes that cybersecurity is not a one size fits all proposition. CMMC defines 5 levels of cybersecurity maturity providing a path to security improvement. For example, CMMC Level 1 focuses on establishing basic levels of security hygiene to protect FCI, while Level 5 defines the most advanced measures designed to protect CUI from APTs.

CMMC Levels and Associated Focus

Level 1

Level 2

Level 3

Level 4

Level 5

Performed — Basic Cyber Hygiene

Documented — Intermediate Cyber Hygiene

Managed — Good Cyber Hygiene

Reviewed — Proactive

Optimizing — Advanced/Progressive

Basic Safeguarding of FCI

Transition Step to Protect CUI

Increasing Protection of CUI

Increasing Protection of CUI

Reducing Risk of APTs

Source: Cybersecurity Maturity Model Certification ver 1.02

The required maturity level a particular organization will need to implement will vary based on a wide variety of factors, such as the size, scope, complexity, types of contracts and sensitivity of the data or information that needs to be protected based on the threats an organization faces.

“Asset Management” is an example of a security domain. A practice in the Asset Management domain, AM.4.226, defines the need to discover and identify systems with specific security related attributes.

Let’s examine CMMC specific practices where ORDR Systems Control Engine (SCE) will benefit you with a coordinated approach to the security of all your devices in a CMMC regulated environment.

Applying ORDR SCE to CMMC Requirements

This section reviews some of the specific CMMC domains and practices related to the security and management of devices in a DIB organization’s environment. We then introduce ways that the ORDR SCE platform can potentially apply to these requirements.

Access Control (AC)

RELEVANT PRACTICES

HOW ORDR CAN HELP

AC.1.001 - Limit information system access to authorized users, processes, or devices

AC.1.002 - Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

AC.1.003 - Verify and control / limit connections to and use of external information systems

AC.4.023 - Control information flows between security domains on connected systems

AC.5.024 - Identify and mitigate unidentified access points connected to the network

The ORDR SCE analyzes the environment to discover and identify all connected devices including unmanaged, IoT, and OT devices. Each device is classified by its type or function (e.g. security camera) and the solution then gives details of the specific device down to the operating system and configuration. ORDR also learns the communication patterns for each device and the other systems it interacts with. This visibility allows organizations to identify all devices, and in the process can reveal any potential rogue access points. Next, ORDR provides visibility into which devices are connecting to which systems and can generate enforcement policies to ensure that only necessary devices are allowed to connect to protected systems. This can provide appropriate isolation policies for devices and their services based on their sanctioned use and can provide additional critical context to support other access solutions such as a NAC deployment. Additionally, traffic analysis can reveal devices that are not employing appropriate levels of encryption.

Asset Management (AM)

RELEVANT PRACTICES

HOW ORDR CAN HELP

AM.4.226 - Employ a capability to identify systems with specific component attributes (e.g. OS type)

ORDR automatically analyzes devices to reveal a variety of detailed device attributes. Depending on the device, this can include manufacturer, model, serial number, operating system traits, installed software, and a wide variety of connectivity traits.

Configuration Management (CM)

RELEVANT PRACTICES

HOW ORDR CAN HELP

CM.2.061 - Establish and maintain baseline inventories and configurations for organizational systems

ORDR’s automated discovery of all connected devices allows organizations to ensure they always have an up to date inventory of their devices including the various types of unmanaged devices that are typically missed in traditional inventory efforts. The solution also delivers visibility into system and connectivity attributes which can be tracked over time.

Incident Response (IR)

RELEVANT PRACTICES

HOW ORDR CAN HELP

IR.2.093 - Detect and report events

IR.2.094 - Analyze and triage events to support event resolution and incident declaration.

ORDR provides alerting of a variety of events including indicators of compromise as well as anomalous or suspicious device behavior. The platform additionally integrates with a variety of additional tools such as SIEMs and IT service management platforms to facilitate the response and resolution of events.

Risk Management (RM)

RELEVANT PRACTICES

HOW ORDR CAN HELP

RM.2.142 - Scan for vulnerabilities in organizational systems

RM.3.144 - Periodically perform risk assessments to identify and prioritize risks according to risk categories, risk sources, and risk measurement criteria.

RM.3.147 - Manage non-vendor-supported products separately and restrict as necessary to reduce risk

ORDR performs a continuous risk assessment of the environment based on observed vulnerabilities and threat-based indicators of risk. ORDR device discovery is enriched with vulnerability database intelligence and optionally integrates with other 3rd party vulnerability scanners like Rapid7 and Tenable. Integration with vulnerability management solutions such as Rapid7 and Tenable allow the ORDR dashboard to incorporate and present risk information from active network scans, while also sending important context to the vulnerability scanner itself. ORDR also ingests data from a variety of external sources such as industry-specific recall databases to identify devices that pose a particular risk. Devices that are recalled, vulnerable, or show signs of compromise can be automatically isolated based on company policy.

Security Assessment (CA)

RELEVANT PRACTICES

HOW ORDR CAN HELP

CA.2.157 - Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

ORDR automatically builds a connectivity flow “genome” for each device. ORDR Flow Genome shows all the systems that a device communicates with including the types of traffic. In addition to showing the connectivity of systems, this visibility is mapped on top of Layer 2 and Layer 3 network topologies to show the devices in relation to VLANs and subnets. Communication of a device to the Internet, in particular to a malicious domain, is also highlighted as a risk.

System Communication and Protection (SC)

RELEVANT PRACTICES

HOW ORDR CAN HELP

SC.1.175 - Monitor, control, and protect organizational communications at external boundaries and key internal boundaries.

As described above, ORDR makes it easy to see exactly how all devices are communicating including traffic to and from the Internet or internal subnets. Communications to a risky or bad domain is identified as a security risk. ORDR can also automatically generate firewall policies to prevent unauthorized access, or alternately can provide staff with the necessary visibility to create policies on a case by case basis.

System Integrity (SI)

RELEVANT PRACTICES

HOW ORDR CAN HELP

SI.5.223 - Monitor individuals and system components on an ongoing basis for anomalous or suspicious behavior.

In addition to monitoring devices for known signs of compromise such as communication with malicious domains or IP addresses, ORDR also monitors the behavior of all connected devices to identify signs of compromise. This can include behaviors that are out of the norm for a particular device type (e.g. HVAC system) or for the specific device in question. This can also identify systems that are attempting to masquerade a different device type such as a compromised laptop attempting to appear like an IoT device to evade security controls.

Conclusion

CMMC compliance will force many organizations to take a fresh look at their cybersecurity program and make changes to align with DoD requirements. Core security functions such as inventory, risk management, and threat detection will be essential to maintaining compliance, and organizations should look for efficient, automated systems that can help provide coverage for all connected devices including unmanaged, IoT, and OT devices. The ORDR SCE can arm organizations with a powerful tool to gain visibility into their environments including all their devices. The solution can then automatically expose potential risk, and enforce policies to either isolate high-risk devices, or to segment systems based on their unique needs. To learn more about ORDR and how the solution can help meet your compliance goals, contact the ORDR team at www.ordr.net.

Frequently asked questions
How do unmanaged devices create CMMC compliance risks?
Unmanaged IoT and OT devices operate outside traditional IT management tools, creating visibility gaps that make it impossible to assess their security posture against CMMC control requirements. These shadow devices can introduce vulnerabilities that auditors will flag during compliance assessments. ORDR's automated discovery identifies these hidden assets across your network, eliminating blind spots in your compliance inventory.
Can you achieve CMMC compliance with devices you cannot directly manage?
Yes, but it requires understanding which CMMC controls apply to each device and implementing practical strategies for devices that cannot be patched or configured directly. ORDR maps discovered assets to specific CMMC maturity levels and control requirements, helping you develop risk-based remediation approaches. This allows you to address compliance gaps without disrupting critical operations.
What's the best way to discover and inventory unmanaged devices for CMMC?
Continuous network visibility is essential—single-point assessments miss devices that connect intermittently or operate in isolated network segments. ORDR provides automated, ongoing discovery of IoT and OT assets that traditional tools miss, building a complete inventory of unmanaged devices across your environment. This intelligence feeds directly into CMMC control mapping and remediation planning.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →